Azure Entra ID Elevation of Privilege Vulnerability
The vulnerability is classified as CWE-285 (Improper Authorization), which means improper verification of access permissions to resources or operations. An attacker can send an appropriately crafted network request to Microsoft Entra ID without needing to possess any credentials. As a result of an authorization error, the system may grant access or permissions exceeding the permitted scope.
An attacker can gain unauthorized access to protected resources or operations within Microsoft Entra ID, leading to high exposure of data confidentiality and limited integrity breach. The vulnerability has a scope beyond the source component (Scope: Changed), which means potential impact on related systems and resources.
Apply patches available from the vendor according to references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24305. In the case of Microsoft cloud services, patches may be deployed automatically — it is recommended to verify the update status in the Microsoft Security Update Guide panel.
Microsoft Entra ID — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NMicrosoft Entra Id
APPMicrosoftall versions
Related vulnerabilities
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg...
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a...
Błąd walidacji źródła w Microsoft Entra ID umożliwia privilege escalation
Obejście uwierzytelnienia w Microsoft Azure Active Directory B2C
Ujawnienie wrażliwych danych w Azure Entra ID umożliwiające spoofing